Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Review the process behind every arrival, move, and departure.

Most privileged-role and licensing findings trace back to how an identity was created, changed, or removed. This review reads the joiner-mover-leaver procedure itself, and checks whether it was actually followed.

Start with the procedure, not the account list.

Most privileged-role and licensing findings trace back to how an identity was created, changed jobs, or left-not to any single setting. This review reads the actual joiner, mover, and leaver procedure alongside evidence of whether it was followed.

New-hire provisioning

Who creates the account, assigns the starting role set and licence, and confirms it matches the job-not a template copied from the last hire.

Role and department changes

Whether access and licence assignments are updated when someone changes role, location, or manager, or simply accumulate alongside the old ones.

Departure and access removal

Who is notified when employment ends, what is disabled immediately versus later, and how contractors and fixed-term staff are handled.

Trace where a broken step actually surfaces.

A missed step in this process rarely shows up as its own finding. It reappears later as a privileged-role assignment nobody can explain or a licence nobody can account for.

Standing privilege with no current reason

Connect an administrative or elevated assignment back to the hire, promotion, or project that originally justified it.

Licensed but inactive accounts

Identify accounts that still hold paid licences and mailbox access weeks or months after the person’s last day.

Shared and orphaned ownership

Find distribution lists, Teams, and SharePoint sites still owned by someone who has moved on or left.

Match the procedure to how the organization actually hires and separates.

A joiner-mover-leaver process only works if it fits how HR, managers, and IT actually communicate-not an idealized flow with no connection to what triggers a ticket.

Trigger and notice

Confirm what event starts the process-an HR system change, a manager email, a signed form-and how reliably it reaches IT.

Manager and HR handoff

Clarify who confirms the access a mover needs and who confirms a leaver’s last day, since IT rarely owns either fact alone.

Contractors and second employers

Extend the same discipline to contractors, temporary staff, and personnel from a partner organization who hold accounts but sit outside the regular HR record.

Turn a gap into an owned fix, not a one-time cleanup.

Disabling today’s stale accounts helps once. A dated process failure needs an owner and a way to notice the next one.

Immediate cleanup vs. process fix

Separate the one-time account cleanup from the procedural change needed so the same gap does not reappear in six months.

A practical recurring check

Define a realistic cadence and owner for comparing active accounts against current staff, sized to the organization rather than a generic quarterly rule.

Evidence for the next reviewer

Keep the updated procedure, its owner, and the date it last worked attached to the record, not only the fixed accounts.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.